CVE-2009-4794
Community CMS 0.5 - SQL Injection via article_id Parameter or Calendar Event Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4794. PoCs published by Salvatore Fresta.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Community CMS 0.5, allowing unauthenticated attackers to extract user credentials via crafted UNION-based queries in view.php and calendar.php.
Description
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Community CMS 0.5, allowing unauthenticated attackers to extract user credentials via crafted UNION-based queries in view.php and calendar.php.